CVE · Medium

CVE-2020-36758 — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36758 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.4.3 3.4.3 2020-09-16

CVE-2020-36758

The RSS Aggregator by Feedzy plugin through version 3.4.2 contains a cross-site request forgery vulnerability in the save_feedzy_post_type_meta() function, which fails to properly validate nonces. An attacker could exploit this flaw by crafting a malicious request that, if clicked by an administrator, would allow modification of post metadata without legitimate authorization. The vulnerability affects unauthenticated users and requires social engineering to succeed but poses a risk to site security and content integrity.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.